Vendor Risk door. DPA chain, questionnaires, monitoring.

Third-party risk, actually managed.

DPA chain, vendor questionnaires, continuous monitoring, RBI outsourcing register, DPDP processor obligations. Every vendor. Every relationship. One workspace. dcomply scores every vendor across 6 risk dimensions (security, financial, operational, reputational, DPDP-specific, cross-border), drafts a DPDP-compliant DPA from vendor metadata, and reassesses on triggers your team defines (renewal, incident, sub-processor change, downgrade).

Security
Compliance
Operations
Financial
Reputation
Strategic
Sound familiar?

If any of this sounds familiar, you're in the right place.

These are the exact sentences we hear on first calls. If two or three of them ring true, dcomply is the workspace you have been trying to build in a spreadsheet.

Your vendor DPAs are in an inbox folder and none of them are versioned.

You cannot answer "who processes our customer data on our behalf" without a two-day exercise.

Your RBI outsourcing register is a spreadsheet.

Vendor risk assessments happen at onboarding and never again.

You have no exit playbook for a critical vendor.

If you're RBI-regulated, the RBI door covers the outsourcing directions specifically.

Your regulator stack

Here's what sits above the foundation.

Vendor risk sits at the intersection of five different regulatory regimes. dcomply ships modules for each layer.

ISO 27001 supplier control (A.5.19-A.5.23)
Supplier register, service delivery monitoring, information security in supplier agreements.
SEBI CSCRF (for listed / market intermediaries)
Third-party service provider evidence, incident response coordination.
GDPR Art 28 (processor obligations)
Mandatory DPA terms, sub-processor register, audit rights.
RBI Outsourcing Directions
RBI-format register, exit playbook, concentration risk monitoring, materiality classification.
DPDP Act 2023 (processor obligations)
The foundation. Section 8 makes Data Fiduciary responsible for every processor. DPA versioning, sub-processor tracking, right-to-audit.
The Problem

Your Vendors Are Your Biggest Breach Risk

Under DPDP Act Section 8, Data Fiduciaries remain liable for how their processors handle personal data

Third-Party Breaches

Over 60% of data breaches originate from third-party vendors. Under the DPDP Act, your organization, not the vendor, faces penalties up to ₹250 Crore for their failures

Manual Assessments Take Weeks

Traditional vendor risk assessments involve spreadsheets, email chains, and weeks of back-and-forth. By the time you finish, the vendor's risk profile has already changed

No Contract Tracking

Most organizations lack standardized vendor contracts with DPDP-specific data protection clauses, breach notification requirements, and data processing limitations

Capabilities

Complete Vendor Risk Lifecycle

AI 6-Dimension Risk Assessment

Every vendor is scored across Data Security (encryption, access controls), Compliance (DPDP adherence, certifications), Operational (BCP, SLA performance), Financial (stability, insurance), Reputational (breach history, regulatory actions), and Strategic (vendor lock-in, exit planning) dimensions.

Automated Vendor Onboarding

Add vendor details and let AI handle the rest. The system generates a risk questionnaire, collects responses, scores the vendor, and flags high-risk areas, reducing onboarding time from weeks to hours.

AI-Generated Contracts

Generate Data Processing Agreements (DPA), NDAs, MSAs, and SLAs with built-in DPDP Act clauses. Contracts include Section 8 processor obligations, breach notification timelines, data principal rights flow-down, and Section 16 cross-border transfer restrictions.

Risk Level Classification

Vendors are automatically classified as Critical, High, Medium, or Low risk based on their composite score. Critical vendors trigger mandatory review workflows and enhanced monitoring requirements.

Re-assessment & Monitoring

Schedule periodic re-assessments based on risk level, quarterly for critical vendors, annually for low-risk. Track score changes over time and get alerts when a vendor's risk profile deteriorates.

Contract Lifecycle Management

Track contract expiry dates, renewal deadlines, and amendment history. Get alerts 90, 60, and 30 days before contract expiry so you never operate with an expired vendor agreement.

How It Works

Vendor Assessment in 4 Steps

From onboarding to contract generation. AI handles the heavy lifting so you can focus on vendor relationships.

Add vendor details

Enter the vendor's name, services, data access level, and processing activities. The AI pre-populates risk factors based on vendor type and industry.

AI runs 6-dimension assessment

Claude AI evaluates the vendor across all six risk dimensions, generating scores and detailed findings for each category with DPDP Act references.

Review risk scores and findings

Review the composite risk score, dimension breakdowns, and specific risk flags. Accept, override, or request deeper analysis on any dimension.

Generate DPDP-compliant contract

With one click, generate a complete vendor contract (DPA, NDA, MSA, or SLA) with all DPDP-required clauses pre-filled based on the assessment results.

Vendor risk FAQs

Questions procurement and DPOs actually ask.

Vendor Risk Management, also called Third-Party Risk Management (TPRM), is the discipline of identifying, assessing and continuously monitoring risks introduced by suppliers and processors that touch your organisation's data or operations. Under the DPDP Act 2023, every processor of personal data on your behalf is your responsibility. An unsigned Data Processing Agreement or an unassessed subcontractor is a compliance gap that could cost up to ₹250 crore.

Effectively yes. Section 8 of the DPDP Act 2023 makes the Data Fiduciary (you) responsible for compliance by any Data Processor it engages. Without documented vendor assessment, DPA signature and periodic re-review you cannot demonstrate the accountability principle to the Data Protection Board. Even a single vendor breach becomes your breach.

dcomply scores every vendor across: (1) security posture (SOC2 / ISO 27001 status, encryption, MFA), (2) financial stability (revenue, funding, insolvency risk), (3) operational reliability (SLA history, redundancy, DR/BCP), (4) reputational exposure (litigation, negative media, regulator actions), (5) DPDP-specific gaps (DPA signed, purpose limitation, retention terms, sub-processor list), and (6) cross-border exposure (data flowing outside India). The composite score drives whether onboarding is auto-approved, needs DPO review, or is blocked.

A Data Processing Agreement is a written contract between a Data Fiduciary and a Data Processor that documents purposes, categories of data, retention, security measures, sub-processor rules, breach notification duty and audit rights. It is required under Section 8 read with the DPDP Rules 2025 draft. dcomply auto-drafts a DPDP-compliant DPA from vendor metadata and lets you send it for e-sign from the vendor record.

Best practice: high-risk vendors annually, medium-risk every 24 months, low-risk on contract renewal. dcomply also triggers ad-hoc reassessment on events: a vendor breach, a new sub-processor, a change in data flow direction (India to offshore), or a downgrade in their SOC2/ISO status.

Yes. Vendors can self-onboard through a public intake form linked to your procurement portal, upload their security artifacts, and receive their auto-generated DPA. Once approved, the vendor record syncs to your master via webhook. dcomply's API plus webhooks allow integration with any procurement or ERP system.

Under DPDP, any processor handling personal data on your behalf needs a written arrangement equivalent to a DPA. Under GDPR Art 28, mandatory. Under RBI outsourcing, mandatory.

No. dcomply hosts the workflow. Your legal team owns the terms.

VSAQ, CAIQ, SIG, plus custom questionnaires you can define.

Vendors are tiered by criticality. Tier-1 gets reassessed annually, sooner if triggered by an incident or a regulatory change.

Native export in the format inspectors expect.

Under DPDP Act Section 8, Data Fiduciaries remain liable for personal data processed by their vendors (Data Processors). If a vendor suffers a breach, your organization faces penalties up to ₹250 Crore. dcomply ensures you assess, monitor, and contractually bind every vendor to DPDP compliance standards before they access personal data.

dcomply's AI generates four types of vendor agreements: DPA, NDA, MSA, and SLA. Each contract includes DPDP-specific clauses for data protection obligations under Section 8, breach notification timelines, data principal rights flow-down, and cross-border transfer restrictions under Section 16. Contracts are tailored based on the vendor's risk assessment results.
Real teams, real programmes

"RBI inspection was one hour."

"We had 340 vendors and no way to tell which handled customer data. Six weeks after switching, we had a tiered register, active DPAs, and a monitoring schedule. RBI inspection was one hour."
Chief Risk Officer, an NBFC.

Take Control of Vendor Risk Today

AI-powered vendor assessments and DPDP-compliant contracts in minutes, not weeks

View All Features